Impact
The Remote Collector configuration process generates a file that disables TLS certificate verification for the Guardian or CMC endpoints, and the tool provides no option to enable it. This misconfiguration allows an attacker positioned between the Collector and the Guardian/CMC to perform a man‑in‑the‑middle attack. The attacker could intercept or modify the sync token, impersonate the server, inject spoofed asset or vulnerability data, or disrupt the communication flow, compromising confidentiality, integrity, and availability.
Affected Systems
Nozomi Networks Remote Collector versions prior to v26.2.0 are affected. Any installation of the Remote Collector that uses the n2os‑tui interface to configure a Guardian or CMC will inherit the disabled TLS validation unless it is manually corrected.
Risk and Exploitability
The CVSS score of 8.3 reflects significant impact. The EPSS score of <1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalogue. Based on the description, it is inferred that the attack vector is a network‑level man‑in‑the‑middle that requires only proximity to the network segment between the Remote Collector and the Guardian or CMC; no authentication or privileged access is needed. The lack of certificate verification provides a clear path for an attacker to intercept traffic, making the risk moderate to high for any organization that relies on the Remote Collector to transmit sensitive information.
OpenCVE Enrichment